Latest / Tech Talks With Kinsoft / McGraw Hill – 13.5M Exposed via Salesforce Misconfig
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Glad to be
- 0:02here. So today's mission is to unpack a really
- 0:06massive cybersecurity failure. And I mean, we
- 0:10want to extract the most vital lessons. about
- 0:13modern software risks from it yeah it's it's
- 0:16a huge topic it really is we're looking at how
- 0:18organizations manage those complex often completely
- 0:22invisible connections between the software they
- 0:25use every single day right and what happens when
- 0:27those connections are just neglected exactly
- 0:30yeah so i want you to imagine for just a second
- 0:33that you're in charge of building an impenetrable
- 0:35digital fortress. Right. You spare absolutely
- 0:38no expense. You got the moats, the armed guards,
- 0:40all of it. Yeah, the state -of -the -art laser
- 0:42grids covering the front door. You are entirely
- 0:44secure. But then, completely by accident, you
- 0:47leave a hidden ground floor side window, just
- 0:49wide open. Oh, man. And not just open, but, like,
- 0:52propped open for literally anyone walking past
- 0:54to see. Right. And this scenario, it isn't some
- 0:57hypothetical nightmare. This is exactly what
- 0:59happened to the K -12 and professional education
- 1:01giant McGraw -Hill in April 2026. Yeah. And it
- 1:05highlights a really painful reality in modern
- 1:08IT infrastructure. You know, you can have the
- 1:12strongest front door in the world. I mean, fortified
- 1:14by multifactor authentication, cutting edge firewalls,
- 1:17the works. Right. But if that side window is
- 1:19left open, threat actors, they don't need to
- 1:22pick a lock. They don't need to deploy some sophisticated
- 1:24malware. They just walk in. They just climb right
- 1:26in. And the resulting fallout is usually staggering.
- 1:29Staggering is really the only word for it. I
- 1:31mean, we are talking about. A data breach exposing
- 1:3513 .5 million accounts. Yeah. And to really grasp
- 1:39the scale of this failure, we first need to look
- 1:42at the timeline, right? The timeline of the attack
- 1:45and the threat actors who actually pulled it
- 1:47off. Definitely. So the breach surfaced in mid
- 1:50-April 2026. That's when this extortion group
- 1:53known as Shiny Hunters. Right. Well -known group.
- 1:55Yeah. They paraded McGraw Hill onto their dark
- 1:57web leak site. Yeah. And they issued a ransom
- 2:00demand. And it had a strict April 14 deadline
- 2:03attached to it. Right. And that use of a public
- 2:05countdown timer, that's a very specific psychological
- 2:07tactic. Oh, really? How so? Well, it's designed
- 2:10to bypass the normal, rational incident response
- 2:13procedures of a corporation. It just creates
- 2:16sheer panic in the boardroom. So they just want
- 2:19to cause chaos. Exactly. They want executives
- 2:22making rushed, fear -based decisions under extreme
- 2:25public pressure. Right. Just hoping they pay
- 2:27up. Yeah. Hoping someone just authorizes a payout
- 2:30to make the whole PR nightmare disappear. But
- 2:32McGraw -Hill, apparently they didn't cave to
- 2:36that pressure or maybe the negotiations just
- 2:39completely broke down behind the scenes. Right.
- 2:41Because when that April 14 deadline passed without
- 2:43a payment, shiny hunters actually followed through
- 2:46on their threat. They dumped over 100 gigabytes
- 2:49of data online. Which is a massive amount of
- 2:51information. It's huge. But looking at the source
- 2:54reports, there's this fascinating detail. Shiny
- 2:57Hunters didn't just list McGraw -Hill on this
- 2:59leak site. They also listed Rockstar Games. And
- 3:02they claim to be holding over 40 million Salesforce
- 3:05records containing PII. Personally identifiable
- 3:08information. Right. Highly personal stuff. Which
- 3:11kind of makes me wonder about the targeting here.
- 3:13Does this mean McGraw -Hill wasn't specifically
- 3:15targeted? That's the million dollar question.
- 3:18Because McGraw -Hill is a massive institution.
- 3:20They have millions of users across schools and
- 3:23corporate training. Why wouldn't they be a high
- 3:26value specific? It just feels like a goldmine,
- 3:30not just some random catch in a dragnet. And
- 3:33if so, how does that change how we should view
- 3:35corporate security? Right. Well, it is a goldmine.
- 3:37But the methodology of how they acquired it,
- 3:41that points directly to a dragnet approach. Explain
- 3:44that. If you look at Shiny Hunter's history,
- 3:47especially a really similar campaign they ran
- 3:50back in 2025, you see their operational model.
- 3:53Right. They aren't spending months trying to
- 3:55crack the... intricate, bespoke security systems
- 3:58of individual companies. That takes too much
- 4:00effort. Exactly. Trying to break down the front
- 4:03door of a company like McGraw -Hill requires
- 4:05massive resources, zero -day exploits, highly
- 4:08specialized skills. The return on investment
- 4:11for the hackers just isn't there when there's
- 4:14an easier path. So if they aren't spending months
- 4:16cracking the core system, they have to be finding
- 4:19a skeleton key somewhere else. Bingo. How does
- 4:22a dragnet actually work in this context then?
- 4:25So they automate the discovery phase. Instead
- 4:27of targeting a specific company, they target
- 4:30a specific vulnerability or a misconfiguration
- 4:34in connected cloud services. Okay. They write
- 4:37scripts that just constantly scan the entire
- 4:39internet. They're pinging millions of servers
- 4:42and API endpoints looking for one specific flaw.
- 4:45Wow. Just sweeping the web. Yeah. And in this
- 4:48case, they were looking for misconfigured Salesforce
- 4:51environments or exposed integrations. So they
- 4:54really do just cast a massive net. Exactly. If
- 4:57you happen to have that misconfiguration, your
- 4:59data gets scooped up automatically. They don't
- 5:01even care who you are. No, they don't care if
- 5:03you're an education publisher like McGraw -Hill
- 5:05or a video game developer like Rockstar Games.
- 5:08To them... Data is just leverage. Man, that really
- 5:11shifts the entire paradigm of how we think about
- 5:14risk. You don't have to be a high -value target
- 5:16to get hit. Not at all. You just have to be making
- 5:18a really common administrative mistake, which
- 5:22honestly brings us to the actual technical mechanism
- 5:24of this brief. Right, the side door. Yeah. According
- 5:27to the reports, McGraw -Hill claimed the leak
- 5:30stemmed from a, quote, limited Salesforce -hosted
- 5:35web page. Notice the phrasing there. Right. They
- 5:38were incredibly quick to insist that there was
- 5:40absolutely no unauthorized access to their core
- 5:42Salesforce accounts, their customer databases,
- 5:44courseware, or internal systems. Right. They
- 5:47even went so far as to state that this appears
- 5:50to be a broader issue involving a misconfiguration
- 5:53within Salesforce's environment that has impacted
- 5:56multiple organizations. Yeah, that right there
- 5:59is a total masterclass in corporate crisis communication.
- 6:02It really is. Notice that careful use of the
- 6:04phrase within Salesforce's environment. Yeah.
- 6:07They are actively attempting to shift the perception
- 6:09of blame right onto their vendor. It's essentially
- 6:13like hiring the best security firm on earth to
- 6:17build a bank vault, right? Right. You have the
- 6:19titanium doors, the time locks, the laser sensors.
- 6:22But then one of your own employees. accidentally
- 6:25tapes the architectural blueprint of the vault,
- 6:28complete with the override codes, to a public
- 6:31billboard out on the highway. Exactly. The bad
- 6:33guys didn't break your vault. The vault worked
- 6:36perfectly. They just bypassed it entirely because
- 6:39you handed them the schematic. That's a great
- 6:41way to put it. And what really raises major questions
- 6:44about this figure pointing is that when journalists
- 6:47reached out to Salesforce for a comment on this
- 6:50supposed broader issue. Yeah, what did Salesforce
- 6:52say? Salesforce gave no response. They totally
- 6:55ghosted the media. Right. And that silence from
- 6:58Salesforce speaks volumes about the shared responsibility
- 7:00model. Which is what exactly? Well, it's arguably
- 7:04the most misunderstood aspect of cloud computing
- 7:07today. OK. When you use a massive platform like
- 7:09Salesforce or Amazon Web Services, Microsoft
- 7:12Azure. Yeah. The vendor is responsible for the
- 7:16security of the cloud. Okay, so the physical
- 7:18stuff. Yes, they secure the physical servers,
- 7:20the data centers, the network infrastructure,
- 7:23and the underlying code of the application itself.
- 7:26But the customer, McGraw -Hill in this scenario,
- 7:29is responsible for security in the cloud. Meaning
- 7:33how they actually use the tool. Exactly. The
- 7:35customer manages their own access controls, how
- 7:38they configure public -facing portals, who they
- 7:40give administrative rights to, and crucially,
- 7:43what third -party applications they integrate
- 7:46into the system. Oh, the integrations. Yeah.
- 7:49Most compromises we see on these platforms do
- 7:51not stem from a flaw in Salesforce's code. They
- 7:54come from the users. Yes. They stem from user
- 7:57end issues, stolen credentials, poor access management,
- 8:00or abused OF apps. Okay, wait. Before we get
- 8:03into the integrations themselves, what exactly
- 8:05is an OF app? Is that like the login with Google
- 8:08or login with Salesforce button I see everywhere
- 8:10on the web? That is exactly what it is. Oh, really?
- 8:13Yeah. OF is an open standard for access delegation.
- 8:16It's what allows you to grant a website or application
- 8:19access to your information. on another website
- 8:22without giving them my actual password exactly
- 8:24so when a marketing tool says connect to salesforce
- 8:27to import your contacts it uses of it asks salesforce
- 8:32for an access token if a mcgraw -hill administrator
- 8:35clicks approve that marketing tool now has a
- 8:39token that acts as a persistent invisible bridge
- 8:42into the salesforce database wow and if i'm understanding
- 8:46this correctly The problem isn't the bridge itself.
- 8:49The problem is how wide you make the bridge and
- 8:51who you let drive across it, right? Precisely.
- 8:53We're talking about over -permissioned integrations.
- 8:55That is the core issue here. Think of an integration
- 8:57token like a valet key for your car. Okay. You
- 9:00give the valet key to the parking attendant so
- 9:03they can park the vehicle. It should only start
- 9:05the ignition and open the driver's door. Right.
- 9:08Nothing else. But if you accidentally give the
- 9:10valet a master key, that also opens the glove
- 9:13box, unlocks the trunk, and contains the code
- 9:16to your home security system. Oh, man. Yeah,
- 9:18you have over -permissioned that key. If that
- 9:21valet key is stolen, the thief has access to
- 9:23everything. But why do companies do this? If
- 9:27IT departments know that over -permissioning
- 9:29is dangerous, why do these master keys get handed
- 9:32out to random marketing tools or connected web
- 9:34pages? It usually just comes down to the friction
- 9:37between business convenience and cybersecurity.
- 9:41The classic battle. Always. Marketing teams,
- 9:43sales teams, customer support, they need to move
- 9:45quickly. They want to launch a new portal or
- 9:48connect a new analytics dashboard today. Right.
- 9:50But the IT security team is often backlogged.
- 9:54So instead of taking the time to painstakingly
- 9:58configure an integration so it only has read
- 10:01-only access to three specific fields. Someone
- 10:04just clicks up. Prove all. Basically. An administrator
- 10:07might just check the box that grants global read
- 10:09and write access to the entire database. It makes
- 10:12the integration work instantly. Which makes the
- 10:14business side happy. Exactly. But it creates
- 10:17a massive silent vulnerability. Because to the
- 10:21system, when that integration asks for data.
- 10:24It looks entirely legitimate. It looks completely
- 10:26normal. The integration has a valid token. It
- 10:29was granted permission by an administrator. So
- 10:31it just lets them in. Yeah. So when the attacker
- 10:33compromises that third -party tool or finds an
- 10:36exposed portal utilizing that token, the system
- 10:38says, sure, here are the 100 gigabytes of data
- 10:41you requested. That is terrifying. It turns the
- 10:44ability to connect software seamlessly into a
- 10:47devastating weapon. The attacker pulls the data
- 10:50without ever triggering an intrusion alarm on
- 10:53the core systems. The systems McGraw -Hill was
- 10:55so eager to defend. Right. The data just leaks
- 10:58out the side window while the armed guards at
- 11:00the front door see absolutely nothing. Exactly.
- 11:03Which really brings us to the human cost of this
- 11:05failure. And honestly, the dizzying corporate
- 11:08spin regarding what was actually stolen. Oh,
- 11:11the spin was intense. Yeah, because... McGraw
- 11:14-Hill immediately deployed a communication strategy
- 11:17focused entirely on what wasn't taken. Right.
- 11:20They announced that no social security numbers
- 11:22were compromised, no financial account information,
- 11:26no student data from their learning platforms.
- 11:29It's the standard playbook for incident response,
- 11:32really. Just calm everyone down. Yeah. The immediate
- 11:34objective is to stop the bleeding of public trust.
- 11:37And the easiest way to do that is to assure people
- 11:39their bank accounts are safe. Which, I mean,
- 11:42I'm certainly glad my credit card isn't floating
- 11:44around the dark web. However, the security tracking
- 11:47site have I been pwned independently confirmed
- 11:50the scope of the 13 .5 million exposed records.
- 11:54And it was a lot. It was. That data included
- 11:56full names, personal phone numbers, email addresses,
- 11:59and actual physical home addresses. Yeah. And
- 12:03yet. McGraw -Hill categorized this as a limited
- 12:07exposure of, quote, non -sensitive data. Right.
- 12:11I have to say, if a criminal syndicate has my
- 12:14full name, the email I use for everything, my
- 12:16personal cell phone number, and the exact physical
- 12:19address where I sleep at night. You don't feel
- 12:20secure. I don't feel like the exposure is limited.
- 12:23I feel entirely compromised. Absolutely. At what
- 12:25point do we as an industry stop letting companies
- 12:28use the phrase nonsensitive data as a get out
- 12:31of jail free card to dismiss massive breaches?
- 12:33Well, you are completely justified in feeling
- 12:36compromised. The phrase nonsensitive is a dangerous
- 12:38myth. Thank you. It really highlights a severe
- 12:41disconnect between corporate liability and individual
- 12:43risk. Oh, so? Well, legally and historically,
- 12:46corporations fixate on social security numbers,
- 12:49health care records and credit card numbers.
- 12:51Right. Because those specific data points carry
- 12:53direct regulatory fines and immediate financial
- 12:55liability. If a credit card is stolen, fraud
- 12:58occurs. Banks initiate chargebacks. So the company
- 13:02actually faces measurable immediate damages.
- 13:04Exactly. The company gets punished. So they care
- 13:06about. that specific data but with names and
- 13:09addresses they don't right but a hundred gigabyte
- 13:12database of verified names active emails personal
- 13:15phone numbers and physical addresses yeah That
- 13:18is the ultimate starter kit for modern cybercrime.
- 13:21Wow. It's the raw material needed to launch devastating
- 13:24secondary attacks. It might not cost McGraw -Hill
- 13:27money today, but it shifts an enormous burden
- 13:30of defense directly onto the individuals. The
- 13:33people whose data was actually exposed. Yes.
- 13:35So walk us through how that secondary attack
- 13:38actually plays out. If a threat actor buys this
- 13:40McGraw -Hill data set off the dark web, what
- 13:43do they actually do with my physical address
- 13:45and my phone number? They use it to craft highly
- 13:47- targeted, socially engineered attacks that
- 13:50just completely bypass your natural skepticism.
- 13:52Okay, give me an example. Let's say you receive
- 13:54a text message on your phone. It addresses you
- 13:57by your first and last name. Cool. It states
- 13:59there's an issue with a package delivery or a
- 14:02municipal utility notice. And it actually includes
- 14:05your physical home address right in the text.
- 14:08Oh, wow. Yeah, and it asks you to click a link
- 14:11to verify delivery instructions. See, my brain
- 14:13immediately drops its guard there. Because if
- 14:16I get a generic text saying your package is delayed,
- 14:18I usually just ignore it. Right. Everyone does.
- 14:21But if the text says, we cannot deliver. to a
- 14:24123 main street and that is my actual house do
- 14:27you pay attention the context makes it feel totally
- 14:29authentic exactly it leverages familiarity to
- 14:33manufacture trust so you click the link which
- 14:36takes you to a spoofed login page for a delivery
- 14:38service or your email provider and i just hand
- 14:41over my password you do or consider how this
- 14:44data is used against your employer attackers
- 14:47use this data set to profile you oh right they
- 14:50call your company's i .t help desk pretending
- 14:53to be you. They say they need to reset your password.
- 14:55And the help desk asks security questions. Right.
- 14:58And when the agent asks for verification, the
- 15:01attacker has your home address, your personal
- 15:04phone number, your personal email address, all
- 15:06ready to go. Because they bought it from the
- 15:08McGraw -Hill leak. Yes. They use that data to
- 15:11authenticate themselves as you, gaining access
- 15:14to your corporate network. Man, the danger really
- 15:17just compounds. It does. I mean, it's technically
- 15:19true that McGraw -Hill didn't lose your social
- 15:22security number or your password. Right. But
- 15:24they handed attackers the exact puzzle pieces
- 15:28needed to trick you into handing those things
- 15:31over yourself. And that is the reality of the
- 15:33threat landscape today. When an organization
- 15:35tells you a breach only involved non -sensitive
- 15:38contact information, you just have to assume
- 15:41that your details are now being actively used
- 15:43to profile you. For sophisticated scams. Yes.
- 15:46You have to become hypervigilant about every
- 15:49unsolicited text, email or phone call that uses
- 15:52your personal information to try and establish
- 15:54credibility. Which is an incredibly heavy burden
- 15:57to carry, especially when you trusted the institution
- 15:59to begin with. Absolutely. And honestly, looking
- 16:02at the entire scope of this breach, there is
- 16:05a profound irony here that is just difficult
- 16:07to ignore. Oh, for sure. We're talking on McGraw
- 16:10Hill. I mean, this is an institution built entirely
- 16:12on. digital learning platforms they provide assessments
- 16:16educational software textbooks every spanning
- 16:18from k -12 classrooms all the way through to
- 16:21professional corporate training environments
- 16:24they are fundamentally in the business of teaching
- 16:27right and yet they just received a very public
- 16:30very painful and very expensive lesson in digital
- 16:33security yeah It serves as the ultimate cautionary
- 16:36tale for any organization operating today. Really?
- 16:40Yeah. It proves that no matter what your core
- 16:42product is, whether you publish textbooks, develop
- 16:45video games, or sell shoes, if you operate in
- 16:48the modern world, you are a technology company
- 16:50first. That's a great point. And if you do not
- 16:52understand the complex web of integrations, APIs,
- 16:55and permissions that make up your digital infrastructure,
- 16:57you are deeply vulnerable. And as we've seen
- 17:00today, that vulnerability isn't always some dramatic
- 17:03hack with a team of cyber criminals deciphering
- 17:06firewalls in a dark room. Usually it isn't. Sometimes
- 17:09it's just a misconfigured setting on a web page.
- 17:12Or an over -permissioned integration token that
- 17:14some administrator approved to save time and
- 17:17then completely forgot about. Which happens every
- 17:19single day. Right. So what does this all mean
- 17:22for you listening? I want to leave you with a
- 17:24thought to mull over, extending beyond just the
- 17:27headlines of this specific breach. Okay. Think
- 17:29about all the third -party apps connected to
- 17:32your own work email or your company software
- 17:34right now. The calendar integrations, the project
- 17:37management tools, the marketing plugins, the
- 17:40simple web portals. There are dozens of them.
- 17:42At least. If a tech -reliant titan like McGraw
- 17:45-Hill can accidentally leave a digital window
- 17:47wide open for anyone to find, how many invisible
- 17:50over -permission connections are quietly sitting
- 17:52in your own organization's tech stack, just waiting
- 17:56for an automated scanner to discover them? It's
- 17:58a scary thought. It really is. To discuss your
- 18:01security and IT needs, visit www .kinsoft .com
- 18:05.au.